Description
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits escalation of privileges through improper handling of content in the DOM within the Content Processes component. The flaw lies in how the application processes DOM elements, potentially allowing an attacker, and it is categorized under CWE‑269 and CWE‑653, indicating an authorization flaw that could be leveraged to bypass expected access controls.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected. All releases prior to version 153 contain the flaw; the issue was fixed in Firefox 153 and Thunderbird 153, so any older installation remains vulnerable.

Risk and Exploitability

The CVSS score of 8.8 marks the flaw as high, but the EPSS score of less than 1% indicates a low probability of exploitation at present and it has not been reported in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malicious content that triggers the DOM parsing process, though specific exploitation conditions are not provided in the advisory. The flaw requires the component to process content in a way that alters privilege boundaries, and would need the target environment to handle such content.

Generated by OpenCVE AI on August 4, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 153 or newer.
  • Upgrade to Thunderbird 153 or newer.
  • Check for unpatched older versions on all client machines and apply the upgrade or mirror the upgrade status with group policy enforcement.

Generated by OpenCVE AI on August 4, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153. Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153.
Title Privilege escalation in the DOM: Content Processes component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-24T20:15:21.451Z

Reserved: 2026-07-20T21:56:32.371Z

Link: CVE-2026-16372

cve-icon Vulnrichment

Updated: 2026-07-22T15:49:59.543Z

cve-icon NVD

Status : Modified

Published: 2026-07-21T13:17:12.377

Modified: 2026-07-24T21:16:43.980

Link: CVE-2026-16372

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:47Z

Links: CVE-2026-16372 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-653

    Improper Isolation or Compartmentalization